GDPR Compliance
Last updated: 12 July 2026
This page sets out how RevestEdu meets its obligations under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, and explains the rights you have over your personal data. It should be read alongside our Privacy Policy.
1. Data controller
RevestEdu is the data controller for the personal data described in our Privacy Policy. [Placeholder — insert registered company name and address here once RevestEdu is formally incorporated.] For any data protection query in the meantime, contact revestedu@outlook.com.
2. Legal basis for processing
- Contract: processing your account and progress data is necessary to provide the service you signed up for.
- Consent: non-essential storage (like the cookie banner itself) is only set after you accept.
- Legitimate interest: basic security and service-reliability logging, kept to the minimum necessary.
3. Your rights
Under UK GDPR, you have the following rights over your personal data:
Right to access
Request a copy of the personal data we hold about you.
Right to rectification
Ask us to correct inaccurate or incomplete data — for example, an out-of-date name or email.
Right to erasure
Ask us to delete your account and personal data, subject to any legal retention requirements.
Right to restrict processing
Ask us to pause processing your data in specific circumstances, for example while a correction request is reviewed.
Right to data portability
Request your data in a structured, commonly-used, machine-readable format to move to another service.
Right to object
Object to processing based on legitimate interest, or withdraw consent for anything we only do with your consent.
4. How to exercise your rights
Email revestedu@outlook.com with your request. We'll respond within one month, as required by UK GDPR — or explain why we need longer for a complex request.
5. Data retention
We retain personal data only for as long as your account is active or as needed to provide the service, after which it's deleted or anonymised, except where we're legally required to retain limited records for longer.
6. International transfers
Our data processor, Supabase, may process data on infrastructure located outside the UK. Where this happens, it's covered by appropriate safeguards such as Standard Contractual Clauses, consistent with UK GDPR requirements for international transfers.
7. Complaints
If you're unhappy with how we've handled your data, please contact us first so we can try to resolve it. You also have the right to lodge a complaint with the UK's supervisory authority, the Information Commissioner's Office (ICO).